Skip to main content

Security and procurement

Evidence for the court's review, without inflated claims.

Court Nox supports security, accessibility, legal, and procurement diligence with a clear distinction between implemented controls, customer-specific configuration, and roadmap work.

Implemented in the platform

Controls that can be traced to the product and deployment.

The list below describes current product design and production configuration. A buyer-specific response may narrow, expand, or condition these statements based on deployment, integrations, contract terms, and the records in scope.

Court-scoped access

Authenticated requests operate in an authorized court context, and court records are queried and changed within that scope.

Role and permission enforcement

Server-side role and permission checks protect administrative, judicial, staff, counsel, and platform-level actions.

Separate user journeys

Court users, counsel, jurors, public responders, and temporary sessions use purpose-specific routes and authorization checks.

Revocable sessions

Inactive accounts are rejected and session versioning allows previously issued application sessions to be invalidated.

Audit-oriented records

Protected workflows record actor, court, action, result, request context, and timing while designated secret fields are redacted.

Sandbox guardrails

Training courts are visibly separated from live courts and server-side policy blocks outbound communications and external integrations.

Protected production edge

The production deployment is configured for HTTPS and keeps application, database, and object-storage services behind the public edge.

Non-destructive training resets

Demo-generated records use an archive-first reset path so training data can be refreshed without silently deleting its history.

Current assurance status

Clear about what is complete.

Requirements vary across state, local, and federal buyers. These statuses prevent a roadmap item from being mistaken for a completed independent assessment or government authorization.

Accessibility

Program underway

WCAG 2.2 Level AA is the product target. A public statement is available; formal evaluation is not yet complete.

ACR / VPAT

Roadmap

The planned package uses the VPAT 2.5Rev WCAG and 508 editions, supported by one documented evaluation program.

SOC 2

Not claimed

Court Nox does not currently represent that it has completed a SOC 2 examination.

FedRAMP, GovRAMP, and CJIS

Not claimed

Court Nox does not currently represent authorization or compliance under these frameworks. Applicable requirements are evaluated with each buyer.

Procurement workflow

Turn requirements into an accountable implementation plan.

  1. 01

    Define scope

    Confirm the court, workflows, users, records, integrations, hosting constraints, and applicable standards.

  2. 02

    Map evidence

    Answer the buyer questionnaire using the deployed architecture, current controls, contracts, and documented gaps.

  3. 03

    Resolve conditions

    Agree on remediation, configuration, data handling, implementation, and acceptance criteria before launch.

  4. 04

    Maintain the record

    Keep approved decisions, security artifacts, accessibility findings, and changes tied to the customer scope.

Buyer questions

Direct answers for common reviews.

For a scoped security questionnaire, data-flow review, or accessibility request, contact info@courtnox.com.

Is Court Nox FedRAMP authorized?

No. Court Nox does not currently claim FedRAMP authorization. We will identify hosting and control gaps plainly when a procurement requires FedRAMP or a state authorization framework.

Does Court Nox have a completed VPAT or Accessibility Conformance Report?

Not yet. Court Nox has published its current accessibility status and is preparing a testing and remediation program before issuing VPAT 2.5Rev WCAG and 508 Accessibility Conformance Reports.

How does Court Nox separate one court from another?

The application uses court-scoped authorization and data access, with role-aware workflows inside the active court context. The exact deployment and isolation requirements are confirmed during procurement.

Can Court Nox respond to a court security questionnaire?

Yes. Responses are grounded in the actual deployment and contract scope. Items that are planned, customer-configured, or not currently supported are identified rather than presented as completed controls.

Accessibility program

Review the current statement and roadmap posture.

Read the accessibility statement